AI, AI, AI. Everyone keeps talking about it. Alright, great! AI! But is it usable without running afoul of the regulations? The AI tools of today did not exist when The Financial Services and Markets Act 2000 (FSMA) or the Consumer Duty were written.
The FCA has made it clear in the 2026 Mills Review: artificial intelligence is governed under existing rules. Whether you use Generative AI, machine learning models or your own expertise, Consumer Duty, SM&CR, and UK GDPR apply as soon as you do a mortgage fact-find, a credit-repair assessment, or an affordability calculation. Nothing has changed here.
However, AI tools, particularly Generative AI, can help you accelerate part of your work and therefore be more efficient. Ignoring them becomes a point on how competitive your business is.
Therefore, let’s look at a framework for governed AI deployment which anchors on a single operating principle: Automation where rules exist. AI where judgement is required.
Here is how modern UK mortgage professionals can scale their advice without falling foul of the regulator.
- Separate the Typing from the Decision
Generative AI is a sophisticated autocomplete engine, not a lookup database of lender criteria. It predicts words through statistical models. It does not “know” underwriting.
The human makes the decision. The AI helps with the write-up.
- Let AI do the heavy lifting: Transcribing advice calls, drafting initial Mortgage Illustration breakdowns, summarising bank statements, or restructuring rough discovery into a clear picture.
- Keep the human at the core: Assessing borrower affordability, testing tolerance to rate shocks, recommending a five-year fixed over a tracker, and assessing vulnerable client circumstances.
Make sure to audit how the AI was used. That will help with a file review when it happens.
For example, you can add a short note in each case file:
“AI was utilized as a drafting tool for [INSERT TASK]. A qualified adviser defined the recommendation and rationale prior to drafting, reviewed and corrected the generated text against source records, and confirmed all facts. The final advice and judgment are strictly those of the adviser.”
- Use AI tools with professional subscriptions, not the free tier
Every current Generative AI tool (Claude, ChatGPT, Grok, Gemini, …) have similar issues.
First, there is a risk of data leakage. Any text or data that you put on these tools can be used for training. Second, the location of the servers is not necessarily guaranteed, putting you at risk under UK GDPR.
Before deciding to use a new AI tool, go through these questions:
- Data Processing Agreement: Is there a data-processing agreement in place?
- Model Training: Is our data used to train their models?
- Data Storage & Jurisdiction: Where is the data stored, and under what law?
- Approved-Tools Policy Listing: Is it on the approved-tools list in our policy?
The first two points are usually solved by using a professional (paid) subscription instead of a free-tier subscription. The tool might even allow you to configure the behaviour.
- Institute the “Never-Paste” Redaction Habit
For additional data safety, think about anonymising the documents you process through the AI tools, particularly the public ones.
Here is one rule to rule them all: anonymise client names, National Insurance numbers, dates of birth, or account numbers.
This takes a few seconds with tools available online, at Microsoft or on the MoiraCorp website (https://moiracorp.com/redactor/).
Your data agreements should cover that. However this adds another layer of safety to your data.
- Cement Personal Accountability (SM&CR)
Software cannot be held accountable under SM&CR, whether it uses AI or not. A Senior Management Function (SMF) holder ultimately is.
If any incident happens with the use of AI, make sure that it is recorded and that the SMF holder is informed. You can do that easily by keeping an incident log that is reviewed on a quarterly basis.
The Real Strategy: An AI policy, One Tool, One Quarter
You know you can save a lot of time by using AI tools, but you are not sure how to go about it.
Here is a simple winning strategy
- Define a one-page AI-policy that is easily understandable by all: Purpose, Approved Tools, Data Rules, Human Checkpoints, Red Lines, Audit Notes, and the Named SMF Owner.
- Choose one high-friction administrative bottleneck that hurts today and identify one vetted enterprise tool to solve it,
- Deploy the vetted tool safely in stages within a single quarter, giving you time to validate and correct if needed.
In one quarter, you will have an AI policy applied, one benefit gained, one tool in use. You will also have a method you can use to rinse and repeat to tackle your other bottlenecks.
